Issue 107: a declaration carries no order; rescue on an enrolled node is reconcile, not apply FILE

Both from the review of the issue-104 fix: a hand-applied file on an enrolled node is
recorded as carried and would remove the foundation, and nothing on the wire orders one
declaration against another.
This commit is contained in:
2026-09-23 23:27:08 +02:00
parent 2445d80565
commit 671c2f3881
2 changed files with 53 additions and 1 deletions
+11 -1
View File
@@ -8,7 +8,7 @@ code:
- mesh-host packaging/nox-mesh-host-network.sh
- mesh-controller internal/token
- mesh-controller internal/inventory/nodes.go
updated: 2026-09-22
updated: 2026-09-23
decisions:
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
@@ -436,6 +436,16 @@ root can already do anything it can. The bound in
[ADR 0005](../../02-DECISIONS/0005-the-node-host.md) is on what a
**remote** party may push, not on what a person at the machine may do.
**But not on a node the mesh has spoken to.** Amended 2026-09-23, after
[issue 104](../../04-ISSUES/104-reconcile-applies-a-stale-declaration-and-refuses-nothing/00-report.md):
once a controller declaration has been kept on the node, `apply FILE` is refused, whatever the
file — a hand-applied file is recorded as *carried*, which the mesh can never remove and reports
as the machine's own, and a declaration carries no order, so the host cannot tell a newer file
from an older one ([issue 107](../../04-ISSUES/107-a-declaration-carries-no-order/00-report.md)).
Rescue on an enrolled node is `reconcile`, which re-applies what the mesh last said, previewed;
`apply FILE` is for a machine before enrolment. A `--rescue` that applies a hand-written file to an
enrolled node under a confirmation is open, not decided.
This replaces the three hand-run scripts that exist today — first node, joining, rescue — with
one binary that has always been the same binary.